Skip to content

Latest commit

 

History

525 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

PRISM

Self-hosted OSINT platform with 26 modules, OPSEC scoring, AI summary, and a real-time web dashboard.

Scan a domain, IP, email, phone or username and get WHOIS, DNS, threat intel, breach data, username search, dark-web mirrors, OPSEC score, entity graphs, and HTML/PDF reports in seconds.

Live Demo · Docker Quick Start · Configuration · Architecture · Security · Changelog · FAQ

CI Version Live Demo Firefox Add-on License

AI analysis on the live demo can be slow. The demo server sits in a region every hosted LLM provider blocks, so its AI calls are routed out through a proxy before they reach a model. It works, it is just slower than a normal instance, so give the summary a minute. A self-hosted instance with your own provider responds at full speed. See the FAQ.

Also from me: Claude Security Skills, eight security skills for Claude Code. Secret scanning, Python SAST, prompt-injection testing, and HTTP, JWT, Dockerfile, CORS and dependency audits. Standard library only, nothing to install.

PRISM Boot Animation


Why PRISM?

  • 26 modules: WHOIS, DNS, crt.sh, Wayback Machine, Shodan, VirusTotal, AbuseIPDB, Censys, dark-web mirrors, email reputation, SMTP verify, breach lookup, Blackbird (50+ sites), Maigret (3000+ sites), Telegram, phone HLR, email headers, file metadata, and more
  • AI summary: written summary of the findings, plus a chat you can ask follow-up questions in. Needs an LLM provider of your own.
  • Real-time dashboard: WebSocket-driven scan progress with per-module progress, an entity graph and a GeoIP map
  • OPSEC Score: aggregated 0-100 exposure risk score across data exposure, identity, infrastructure and web security
  • HTML, PDF, CSV & Markdown reports: export full scan results as HTML, PDF, CSV, or Markdown (locale-aware EN/RU/DE)
  • Multi-language UI: English, Russian, German, French, Spanish, Italian, Polish, Portuguese, and Chinese out of the box (i18n + auto-detect)
  • Standalone CLI: run scans headlessly via python cli.py scan example.com --json, and manage scheduled re-scans with python cli.py watchlist add example.com --interval 6
  • Scan history & comparison: browse past scans, load results, compare two scans side-by-side
  • Webhook callbacks: get notified on scan completion with HMAC-signed payloads (SSRF-protected), Slack/Discord formatters
  • Hardened auth: header-only API keys (X-API-Key / Bearer), no query-string secrets, strict CORS, per-principal scan isolation
  • Zero mandatory API keys: 16 out of 26 modules work without any keys at all
  • One-command deploy: docker run ghcr.io/novacode37/prism-platform with nothing to build (amd64 and arm64)
  • MIT licensed, and adding a module means one file in modules/

Overview

PRISM queries 20-odd external sources and puts what comes back in one place. Targets can be a domain, an IP, an email, a phone number or a username. Results land in a dashboard as they arrive, with a relationship graph, a GeoIP map, an exposure score and HTML or PDF export.

Stack:

  • Backend: Python 3.10+, FastAPI, asyncio, WebSocket, Pydantic, slowapi (rate limiting), xhtml2pdf (PDF)
  • Frontend: Next.js 15 (App Router), React, TypeScript, Tailwind CSS, Leaflet (maps)
  • AI: OpenRouter (Nvidia Nemotron) or Groq (Llama-3) for summary and chat
  • Infrastructure: Docker, docker-compose, GitHub Actions CI/CD
  • Tests: pytest, 435 cases, network mocked

PRISM Dashboard

Architecture (high level)

flowchart LR
    U[User / Browser] -->|HTTPS + X-API-Key| FE[Next.js 15 Dashboard]
    FE -->|REST + WebSocket| API[FastAPI Backend]
    API --> SCH[Scan Orchestrator<br/>asyncio + queues]
    SCH --> MOD[26 OSINT Modules]
    MOD --> EXT[(External APIs<br/>Shodan / VT / Censys<br/>crt.sh / Wayback / etc.)]
    SCH --> CACHE[(Module Cache<br/>TTL JSON)]
    SCH --> STORE[(Scan Storage<br/>per-principal)]
    SCH --> WH[Webhook Dispatcher<br/>HMAC + SSRF guard]
    API --> AI[AI Summary / Chat<br/>OpenRouter / Groq]
    API --> RPT[Report Generator<br/>HTML + xhtml2pdf]
Loading

How it compares

SpiderFoot, theHarvester, Recon-ng and Maltego all cover ground PRISM does, and several of them cover it better. theHarvester and Recon-ng are CLI tools and comfortable to script around. SpiderFoot has far more modules. Maltego's graph work is a different league.

What PRISM does that those generally do not: results stream into a browser while the scan runs, everything is one container with no keys required to get started, and the scan ends with a report you can hand to someone who is not an analyst. If you want depth and already live in a terminal, SpiderFoot or Recon-ng is probably the better tool. If you want to point something at a domain and read the answer, this is built for that.


Use cases

  • Bug bounty recon: kick off a single scan and get subdomains (crt.sh + Censys), open ports (Shodan), wayback sensitive paths, and AI-prioritized findings.
  • Phishing investigation: pivot from a suspicious domain or email to threat intel, breach exposure, mail auth (SPF/DKIM/DMARC), and historical snapshots.
  • Brand & impersonation monitoring: webhook-driven scans to detect new lookalike subdomains, dark-web mentions, and exposed credentials.
  • Security awareness training: give employees their own OPSEC score across email, phone, and username so they see exposure on a 0-100 scale.
  • Academic / educational OSINT: a self-hosted, MIT-licensed reference for teaching passive reconnaissance, geolocation, and threat intel pipelines.

Features

Module Description API Key
WHOIS Domain registration, registrar, dates none
DNS A, MX, NS, TXT, CNAME, SOA records none
Certificate Transparency Subdomain discovery via crt.sh none
Wayback Machine Historical snapshots, sensitive URL patterns none
GeoIP IP geolocation, ASN, timezone ipinfo.io
Shodan Open ports, services, known CVEs; falls back to the keyless InternetDB dataset Shodan (optional)
Censys Host services, ASN, certificate → subdomain discovery Censys
VirusTotal Domain/IP reputation, malware detections VirusTotal
AbuseIPDB IP abuse confidence score AbuseIPDB
Dark Web Checker .onion mirrors via Ahmia + DarkSearch none
Infostealer Exposure Machines infected by stealers carrying the target's credentials (opt-in) Hudson Rock
Domain Exposure Yearly exposure trend, malware families, affected services (opt-in) Lunar
Website Analyzer Tech stack, emails, social links, metadata none
Email Reputation DNS-based email rep (MX, SPF, DMARC, disposable check) none
SMTP Verify Mailbox existence check via SMTP handshake none
Breach Check Email breach / credential leak lookup Leak-Lookup
Blackbird Username presence across 50+ platforms (async) none
Maigret Deep username search across 3000+ sites (not bundled in the Docker image) none
Telegram Lookup Username/ID lookup via Bot API + scraping Telegram
Phone / HLR Number validation, carrier, country, reverse lookup Numverify
Email Headers SPF/DKIM/DMARC analysis, routing hops, spoofing detection none
File Metadata EXIF, GPS coordinates, PDF/DOCX properties none
OPSEC Score Aggregated 0-100 exposure risk score none
Entity Graph Interactive node-relationship visualization none
HTML / PDF Report Self-contained styled report (HTML + xhtml2pdf), localized EN/RU/DE none
AI Summary Natural-language findings summary via LLM OpenRouter / Groq
Webhook Callbacks HMAC-signed POST on scan completion (SSRF-guarded) none

Infostealer Exposure and Domain Exposure are off unless you set HUDSONROCK_ENABLED or LUNAR_ENABLED. Both query a third party, so a default install sends them nothing. Lunar builds its report on the first request and caches it for a month, so a domain nobody has looked up yet comes back as skipped with GENERATING_REPORT. Scan it again once the report is ready.


Showcase

Scan Progress

Findings + OPSEC Score

AI Summary

Browser Extension

Right-click any domain, email, username or IP and the full scan runs inside the popup. No tab switching, no copy-paste.

Get PRISM on Firefox Add-ons

PRISM browser extension demo

More screenshots (domain / IP / email / phone / username / standalone tools)

Domain Scan

WHOIS, DNS, threats, Wayback, GeoIP map, entity graph.

WHOIS

DNS

Threats

Wayback

GeoIP Map

Entity Graph

Raw JSON

IP Scan

VirusTotal + AbuseIPDB threat intel, GeoIP map, entity graph.

IP Threats

IP Map

Email Scan

DNS-based reputation, SMTP mailbox verification, breach check.

Email Rep

Email Findings

Phone Scan

Number validation, carrier detection, country/region, timezone, reverse lookup.

Phone Intel

Phone Map

Username Scan

Blackbird async search across 50+ platforms.

Accounts

Username Graph

AI Analysis

LLM-powered OSINT summary + interactive chat.

AI Chat

Standalone Tools

File Metadata (EXIF/GPS), Email Header Analyzer, Crypto Address Lookup, QR Code Decoder.

File Metadata

Email Headers

Crypto Lookup

QR Decoder


Quick Start

Try in 60 seconds (no setup, no API keys)

A self-contained demo preloaded with example scans. No API keys, no external lookups:

git clone https://github.com/NovaCode37/Prism-platform.git
cd Prism-platform
docker compose -f docker-compose.demo.yml up --build

Open http://localhost:8080. The Next.js UI and FastAPI backend are served by the same container. Three sample scans (a domain, an IP, and a username) are already under Recent Scans, showing the dashboard, OPSEC score, entity graph, map, and HTML/PDF report.

The demo runs anonymously (ALLOW_ANON_API=true) on :8080. For authenticated production-style setup, use the Docker / Manual setups below.

Docker (recommended)

Nothing to clone and nothing to build:

docker run -p 8080:8080 -e ALLOW_ANON_API=true ghcr.io/novacode37/prism-platform:latest

Images are published for linux/amd64 and linux/arm64, so this works on a Raspberry Pi or an ARM VPS as well. Tags follow releases: latest, 2.10, 2.10.0, plus edge built from main.

If you need somewhere to put it, Timeweb Cloud rents plain Linux servers by the month. That is a referral link: same price to you, and it pays for this project's domain.

To configure it, pass an env file instead:

curl -O https://raw.githubusercontent.com/NovaCode37/Prism-platform/main/.env.example
docker run -p 8080:8080 --env-file .env.example ghcr.io/novacode37/prism-platform:latest

Building it yourself works too, and is what you want if you are changing the code:

git clone https://github.com/NovaCode37/Prism-platform.git
cd Prism-platform
cp .env.example .env        # local/demo defaults to anonymous access; edit for production keys
docker compose up --build

Open http://localhost:8080. Docker builds the Next.js static export and serves it from FastAPI together with /api/*, /ws/*, and /healthz.

The container runs as uid 1000, not root. If you mount ./results from a directory owned by someone else, reports will fail to write. chown -R 1000:1000 results on the host fixes it.

The example .env is intentionally easy to run: ALLOW_ANON_API=true and no API key is required. Before exposing PRISM beyond your machine, switch to API-key mode as shown in API keys and anonymous mode.

Manual

# 1. Backend
git clone https://github.com/NovaCode37/Prism-platform.git
cd Prism-platform
pip install -r requirements.txt
cp .env.example .env
python -m uvicorn web.app:app --host 0.0.0.0 --port 8080 --reload --no-proxy-headers

# 2. Frontend (in a separate terminal, from repo root)
cd frontend
npm install
# create .env.local for the separate dev server:
#   NEXT_PUBLIC_API_URL=http://localhost:8080
#   NEXT_PUBLIC_BASE_PATH=
#   NEXT_PUBLIC_API_KEY=<only when ALLOW_ANON_API=false>
npm run dev

Open http://localhost:3000.

When you run only uvicorn from source, FastAPI serves /api/*, /ws/*, and /healthz. The root page / needs a built Next.js export in frontend/out; on a fresh checkout without that build it returns {"detail":"Frontend build not found"}. Use npm run dev as shown above, or run npm run build before serving the single-container style UI from FastAPI.

For local experimentation, .env.example uses ALLOW_ANON_API=true. For any shared or public deployment, set ALLOW_ANON_API=false, configure API_KEYS, and give the UI one accepted key.


Configuration

PRISM starts with no configuration: the Docker command above works as it is. Every external provider key is optional, and a module without its key reports itself as skipped rather than failing the scan.

The handful most people touch:

Variable What it does
ALLOW_ANON_API true lets anyone who can reach the server run scans. Right for a laptop, wrong for anything internet-facing
API_KEYS Comma-separated accepted keys, each with its own isolated scan history
TRUST_PROXY_HEADERS + FORWARDED_ALLOW_IPS Needed behind nginx or Caddy, so rate limiting sees the real client address
PRISM_BASE_PATH Serve PRISM under a subpath such as /prism
MODULE_PROXY / LLM_PROXY Route module and AI traffic through a proxy (guide)
OPENROUTER_API_KEY / GROQ_API_KEY Turn on the AI summary and chat

Every variable, both auth modes in full, the nginx and Caddy examples, subpath deployments and the provider keys with their free tiers are in docs/CONFIGURATION.md.


API

The backend exposes a REST + WebSocket API. Application requests require an X-API-Key or Authorization: Bearer header in API-key mode; in anonymous mode (ALLOW_ANON_API=true) the header can be omitted. /healthz stays unauthenticated. Interactive docs are served at /docs (Swagger) and /redoc when running locally (unless DISABLE_DOCS=true).

Method Endpoint Description
POST /api/scan Start a scan ({ target, scan_type, modules }) → returns scan_id
GET /api/scan/{id} Scan status and results
GET /api/scan/{id}/graph Entity relationship graph
GET /api/scan/{id}/map GeoIP map markers
GET /api/scan/{id}/report HTML report
GET /api/scan/{id}/report/pdf PDF report
GET /api/scans List past scans (per-principal)
GET /healthz Unauthenticated health check
GET /api/health Unauthenticated health check for uptime monitors and load balancers
WS /ws/{scan_id} Live scan progress stream
POST /api/ai/summary, /api/ai/chat AI summary and Q&A
POST /api/url-scan, /api/mac-lookup, /api/crypto, /api/darkweb, /api/qr-decode, /api/email-headers, /api/metadata Standalone tools

Authenticated example:

curl -X POST http://localhost:8080/api/scan \
  -H "X-API-Key: $API_KEY" -H "Content-Type: application/json" \
  -d '{"target":"example.com","scan_type":"domain"}'

Project Structure

prism/
├── config.py                     # Environment + API key loader
├── requirements.txt
├── Dockerfile
├── docker-compose.yml
│
├── modules/
│   ├── extra_tools.py            # WHOIS, GeoIP, DNS, Website Analyzer
│   ├── cert_transparency.py      # Subdomain discovery via crt.sh
│   ├── threat_intel.py           # VirusTotal + AbuseIPDB
│   ├── shodan_lookup.py          # Shodan host intelligence
│   ├── censys_lookup.py          # Censys host + certificate search
│   ├── wayback.py                # Wayback Machine snapshots + sensitive URLs
│   ├── onion_checker.py          # .onion mirror checker (Ahmia + DarkSearch)
│   ├── darkweb_search.py         # Dark-web mentions search
│   ├── blackbird.py              # Username search (async, 50+ platforms)
│   ├── maigret_wrapper.py        # Deep username search (3000+ sites)
│   ├── hlr_lookup.py             # Phone validation + reverse lookup
│   ├── hunter.py                 # DNS-based email reputation check
│   ├── smtp_verify.py            # SMTP mailbox existence verification
│   ├── leak_lookup.py            # Email breach / credential leak lookup
│   ├── telegram_lookup.py        # Telegram username/ID lookup
│   ├── email_header_analyzer.py  # SPF/DKIM/DMARC + hop analysis
│   ├── metadata_extractor.py     # EXIF/PDF/DOCX + GPS extraction
│   ├── crypto_lookup.py          # Crypto address heuristics
│   ├── qr_decoder.py             # QR image decoder
│   ├── url_scanner.py            # Standalone URL scanner
│   ├── opsec_score.py            # Exposure risk scoring (0-100)
│   ├── graph_builder.py          # Entity relationship graph data
│   ├── report_generator.py       # Jinja2 HTML report + xhtml2pdf PDF
│   └── report_i18n.py            # Report translations EN / RU / DE
│
├── web/
│   ├── app.py                    # FastAPI + WebSocket scan engine
│   └── security.py               # Auth, CORS, rate limiting, SSRF guard
│
├── frontend/                     # Next.js 15 + TypeScript + Tailwind
│   └── src/
│       ├── app/                  # App Router pages
│       ├── components/           # UI (Topbar, Sidebar, Map, Graph, ...)
│       └── lib/                  # API client, i18n, types
│
└── tests/                        # 435 pytest tests
    ├── test_modules.py
    ├── test_modules_extended.py
    ├── test_v2_1_modules.py
    └── test_webhook.py

Running Tests

pip install pytest pytest-cov pytest-asyncio
pytest -q
# or with coverage:
pytest tests/ -v --cov=modules --cov=web --cov-report=term-missing

Frontend type check:

cd frontend
npx tsc --noEmit -p tsconfig.json

CI/CD

GitHub Actions pipeline (.github/workflows/ci.yml):

  1. Lint: flake8
  2. Test: pytest with coverage
  3. Build: Docker image

Roadmap

Everything through 2.10 has shipped. The full history, release by release, is in the changelog.

v2.11 (planned)

  • Username checks for the sites that serve identical HTML for every name: needs their APIs rather than page scraping
  • (exploring) AI OSINT agent: autonomous multi-module investigation

Want to contribute? Pick an open issue tagged good first issue or open a new one.


Star History

Star History Chart

Legal Notice

This tool is intended exclusively for lawful, authorized use:

  • Security assessments and penetration testing you are authorized to perform
  • Research on infrastructure, accounts, or data you own or have explicit permission to investigate
  • Auditing your own digital footprint
  • Academic and educational purposes

Every scan PRISM performs is passive and queries only publicly available data, but aggregating public data can still cause real harm. Do not use PRISM to:

  • Stalk, harass, dox, or surveil any person without their consent
  • Profile or track individuals you have no authorization to investigate
  • Collect data in violation of applicable law or the terms of service of the platforms involved

You are responsible for how you use the results. The author assumes no liability for misuse.


Support the project

If PRISM is useful to you, a ⭐ is the best free way to help. If you'd like to support development financially:

USDT (TRC20): TEdN41cTdAyNm7vrP4NYceT9sVhTB9BHho
TON:          UQAkpcYb0hKgqEwGLs08syU_4Nh-_MhwaJT3HPWqFSidLThV
BTC:          bc1qm8zvvh2ehv3m2su6u0exmcr903cf07gn0r66y6
ETH:          0x0639476A71255FD2C15dceD53e167952DcddEE8A

USDT (TRC20)

TON

BTC

ETH

Costs you nothing

These are referral links. Sign up through one and I get a cut, you pay the same as you would anyway.

  • StealthSurf VPN (web), if you want one for OSINT work
  • Telegram Wallet, for the crypto above without an exchange account
  • YepShop, VPN and proxy subscriptions, handy if you want a proxy for MODULE_PROXY

Want the browser extension in your store? The PRISM extension is live on Firefox Add-ons. Publishing it to the Chrome Web Store, Yandex, or other markets costs a registration fee per store. If you want it listed in a specific one, a donation covers that and funds further development. Reach out and I'll ship it.


FAQ

Do I need API keys? No. 16 of 26 modules work without any keys.

Is it free? Yes, MIT licensed and completely self-hosted.

Can I run it without installing anything? Try the live demo, or spin it up with the one-command Docker demo.

Which LLM does the AI summary use? Any OpenAI-compatible endpoint. OpenRouter, Groq, GigaChat and a local Ollama all work. Set LLM_BASE_URL, LLM_API_KEY, and LLM_MODEL in .env to point at your own provider, plus LLM_PROXY if the request needs to go through a proxy. Every key you configure becomes a provider, and they are tried in order until one answers, so a blocked or rate-limited provider falls through to the next.

How do I run the AI locally, with nothing leaving the machine? The compose file ships an Ollama service behind a profile, so it stays out of the way unless you ask for it:

docker compose --profile ollama up -d
docker compose exec ollama ollama pull qwen2.5:3b

Then point PRISM at it in .env. The container reaches Ollama by service name, and no key is needed:

LLM_BASE_URL=http://ollama:11434/v1/chat/completions
LLM_MODEL=qwen2.5:3b

Budget roughly 4 GB of RAM for a 3B model and 8 GB for a 7B one; answers are slower than a hosted provider, and nothing is sent off the machine.

Why do some modules fail on the public demo? The demo is a shared-hosting instance with anonymous access and a daily scan quota, so it hits limits the average self-hosted install never will. Several modules also depend on third-party services that break on their own schedule. crt.sh regularly answers 502, and the Wayback CDX API answers 503 under load. PRISM reports those upstream failures verbatim instead of hiding them.

Why is AI analysis slow on the demo? Hosted LLM providers block the demo's hosting region at their edge, so a direct call never reaches a model. The demo works around it by routing the AI calls out through a proxy in an allowed region. That extra hop costs time, so a summary can take up to a minute or two. It is not broken, just slow, and if a request times out, generating it again usually works. PRISM tries every provider you configure and reports what each one said.

On your own instance there is no proxy hop and it responds at full speed. Point it at any OpenAI-compatible endpoint:

LLM_BASE_URL=https://your-provider/v1/chat/completions
LLM_API_KEY=...
LLM_MODEL=...

Or run the model yourself with nothing leaving the machine, see the Ollama answer above. Configure more than one provider and PRISM falls through to the next when one refuses.


Contributing

Contributions are welcome! Please read CONTRIBUTING.md before submitting a pull request! For security issues, see SECURITY.md.


Also from this project

claude-security-skills: eight security skills for Claude Code: secret scanning, Python SAST, prompt-injection testing, and HTTP, JWT, Dockerfile, CORS and dependency auditing. Standard library only, installable as a plugin.


Development note

PRISM is built by one person, with AI assistance as part of the workflow. Everything gets reviewed and tested before it lands: 435 tests covering module mocking, SSRF and auth, and reverse-proxy behaviour. Bug reports and pull requests are welcome.


Credits

PRISM stands on the shoulders of excellent open-source projects and public data sources.

Tools & techniques

  • Maigret: username search across thousands of sites (run as a subprocess; included in requirements.txt, not in the Docker image, where the module reports itself as skipped)
  • Username heuristics inspired by Sherlock and Blackbird

Data sources & APIs

  • crt.sh, Wayback Machine, Shodan, VirusTotal, AbuseIPDB, Censys, Ahmia, XposedOrNot, ipinfo.io, CoinGecko, BlockCypher, blockchain.info, Ethplorer, api.qrserver.com

Core libraries

  • Backend: FastAPI, Uvicorn, Pydantic, SQLAlchemy, slowapi, phonenumbers, dnspython, python-whois, Pillow, xhtml2pdf
  • Frontend: Next.js, React, Tailwind CSS, Leaflet

Each project is the property of its respective authors and used under its own license. PRISM itself is MIT-licensed.


License

MIT

About

Self-hosted OSINT platform. Point it at a domain, IP, email, phone or username and 26 modules run in parallel: WHOIS, DNS, threat intel, breaches, username search. One dashboard, an exposure score, an entity graph, HTML and PDF reports.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

231 stars

Watchers

8 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages